Cybersecurity topic

Critical Infrastructure

Cybersecurity incidents and defensive changes affecting energy, water, transportation, healthcare, industrial systems, and other essential public services.

Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

WatchTowr confirmed active in-the-wild exploitation of CVE-2026-5430 in WSO2 API Manager (CVSS 9.8), capturing forged admin-privilege JWT tokens on its honeypot network on September 13, 2026; vendor fixes ship as pull requests and update levels spanning API Manager 4.1.0 through 4.6.0, API Control Plane, Traffic Manager, and Universal Gateway. Acronis separately reported limited, targeted exploitation of CVE-2026-87886 in its cPanel/WHM backup plugin based on a single customer report, while CISA added CVE-2026-76461, a Cisco Secure Email Gateway SQL injection, to its Known Exploited Vulnerabilities catalog.

Read this edition

Week in review: Linux rootkit deployed on F5 BIG-IP APM devices, Cisco FMC bugs exploited

Cisco confirmed that state-sponsored and ransomware actors are actively exploiting CVE-2026-20079, an authentication bypass in Secure Firewall Management Center, and N-able shipped an emergency hotfix for CVE-2026-86218, a pre-auth RCE in N-central already exploited in the wild. Sophos separately reported a Linux rootkit on compromised F5 BIG-IP APM appliances that keeps its web shell in memory to evade disk-based detection, while the Dutch NCSC issued an imminent-exploitation warning for two Check Point VPN flaws (CVE-2026-85102, CVE-2026-85103) for which no public proof-of-concept exists yet.

Read this edition

Hackers exploit new MikroTik RouterOS flaws to hijack routers

Poland's CERT confirmed active exploitation of the "MikroTrick" chain—CVE-2026-67276, an SSH authentication bypass via incomplete RSA public-key validation, followed by CVE-2026-86060, a privilege escalation through crafted usernames—against internet-exposed RouterOS devices, and MikroTik shipped fixes in RouterOS 7.25beta3, 7.24.2, 7.23.4, and 6.49.21 on September 3, with the CERT recommending isolation, log preservation, factory reset, and credential rotation for suspected compromises. Separately, N-able released N-central 2026.3 Hotfix 4 to address CVE-2026-86218, a maximum-severity RCE in its RMM platform that allows unprivileged threat actors to execute malicious code, though the company has not confirmed in-the-wild exploitation while Huntress flagged the flaw as a potential zero-day and Shadowserver tracks nearly 1,500 N-central servers exposed online.

Read this edition

What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree

Sygnia confirmed that the Fire Ant actor deployed purpose-built implants on Cisco IOS XR routers and TACACS servers that filter log output, hide GRE tunnel configuration from administrators, and exfiltrate credentials through a tac_plus library-injection technique it tracks as TacTap, with IoCs and YARA rules published for defensive validation. CISA added CVE-2026-60004 (Gitea code injection) and CVE-2026-8452 (Citrix NetScaler) to its KEV catalog, confirming active exploitation of both, while Shadowserver reported at least 274 internet-facing Zimbra instances already compromised via CVE-2026-73570.

Read this edition

PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions

PaperCut has confirmed active zero-day exploitation across all NG and MF versions, released emergency patches for v25 and v26, and directed internet-exposed servers to immediately restrict access to trusted IP addresses while its investigation continues. Separately, McKesson disclosed a breach it detected on August 25, while ShinyHunters alleges it used vishing to compromise Okta accounts and exfiltrate roughly 1 TB of patient data over four days—claims McKesson has not independently confirmed as its investigation remains in early stages.

Read this edition

Unknown PaperCut NG/MF vulnerability is under active attack

PaperCut confirmed active exploitation of an unspecified NG/MF vulnerability and issued specific remediation—restrict Application Server web access to trusted IPs and hunt for truncated server.log files or suspicious pc-app.exe post-exploitation activity—while CISA added Citrix NetScaler CVE-2026-8452 to its KEV Catalog after watchTowr demonstrated root-level RCE beyond Citrix's initial DoS-only assessment, setting an August 29 federal patch deadline. Separately, the FBI and DOJ seized domains that rendered QTFY's QScan and QTRouter tools inoperable, dismantling the obfuscation network behind intrusions targeting NASA, the Federal Reserve, and the U.S. Senate.

Read this edition

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

CISA listed CVE-2026-60004 in its KEV catalog after confirming in-the-wild exploitation of Gitea's diffpatch endpoint, where an attacker with repository write access—trivially obtained via default open registration—plants a malicious Git hook to execute arbitrary shell commands as the Gitea OS user; the vulnerability spans all versions from 1.17 and is fixed in 1.27.1, and one documented hit showed a dropper that cleared LD_PRELOAD, killed competing high-CPU processes, and pulled an architecture-specific miner payload over HTTPS. SOCRadar separately detailed AnonyMousKIT, a credit-metered PhaaS platform active since early 2024 that deploys AI voice agents to call owners of stolen Apple devices and harvest their passcode, Apple ID, and live 2FA code to bypass Activation Lock; 200 recovered calls ran from August 2025 to May 2026 (179 to Brazilian numbers), and the researchers recommend moving high-value Apple IDs to hardware security keys to neutralize the real-time 2FA interception the platform targets.

Read this edition